CVE-2017-4960

Source
https://cve.org/CVERecord?id=CVE-2017-4960
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-4960.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2017-4960
Aliases
Published
2017-03-10T01:59:00.143Z
Modified
2026-07-08T05:49:46.696592200Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

An issue was discovered in Cloud Foundry release v247 through v252, UAA stand-alone release v3.9.0 through v3.11.0, and UAA Bosh Release v21 through v26. There is a potential to subject the UAA OAuth clients to a denial of service attack.

Database specific
{
    "unresolved_ranges": [
        {
            "cpes": [
                "cpe:2.3:a:pivotal_software:cloud_foundry:247.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:pivotal_software:cloud_foundry:248.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:pivotal_software:cloud_foundry:249.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:pivotal_software:cloud_foundry:250.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:pivotal_software:cloud_foundry:251.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:pivotal_software:cloud_foundry:252.0:*:*:*:*:*:*:*"
            ],
            "extracted_events": [
                {
                    "introduced": "247.0"
                },
                {
                    "last_affected": "247.0"
                },
                {
                    "introduced": "248.0"
                },
                {
                    "last_affected": "248.0"
                },
                {
                    "introduced": "249.0"
                },
                {
                    "last_affected": "249.0"
                },
                {
                    "introduced": "250.0"
                },
                {
                    "last_affected": "250.0"
                },
                {
                    "introduced": "251.0"
                },
                {
                    "last_affected": "251.0"
                },
                {
                    "introduced": "252.0"
                },
                {
                    "last_affected": "252.0"
                }
            ],
            "vendor_product": "pivotal_software:cloud_foundry",
            "source": "CPE_STRING"
        },
        {
            "cpes": [
                "cpe:2.3:a:pivotal_software:cloud_foundry_uaa:3.9.0:*:*:*:*:*:*:*"
            ],
            "extracted_events": [
                {
                    "introduced": "3.9.0"
                },
                {
                    "last_affected": "3.9.0"
                },
                {
                    "introduced": "3.9.0"
                },
                {
                    "last_affected": "3.9.0"
                }
            ],
            "vendor_product": "pivotal_software:cloud_foundry_uaa",
            "source": "CPE_STRING"
        }
    ]
}
References

Affected packages

Git / github.com/cloudfoundry/uaa

Affected ranges

Type
GIT
Repo
https://github.com/cloudfoundry/uaa
Events
Database specific
{
    "cpe": [
        "cpe:2.3:a:pivotal_software:cloud_foundry_uaa:3.9.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:pivotal_software:cloud_foundry_uaa:3.9.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:pivotal_software:cloud_foundry_uaa:3.9.2:*:*:*:*:*:*:*",
        "cpe:2.3:a:pivotal_software:cloud_foundry_uaa:3.9.3:*:*:*:*:*:*:*",
        "cpe:2.3:a:pivotal_software:cloud_foundry_uaa:3.9.4:*:*:*:*:*:*:*",
        "cpe:2.3:a:pivotal_software:cloud_foundry_uaa:3.9.5:*:*:*:*:*:*:*",
        "cpe:2.3:a:pivotal_software:cloud_foundry_uaa:3.9.6:*:*:*:*:*:*:*",
        "cpe:2.3:a:pivotal_software:cloud_foundry_uaa:3.9.7:*:*:*:*:*:*:*",
        "cpe:2.3:a:pivotal_software:cloud_foundry_uaa:3.9.8:*:*:*:*:*:*:*",
        "cpe:2.3:a:pivotal_software:cloud_foundry_uaa:3.10.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:pivotal_software:cloud_foundry_uaa:3.11.0:*:*:*:*:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "3.9.0"
        },
        {
            "last_affected": "3.9.0"
        },
        {
            "introduced": "3.9.1"
        },
        {
            "last_affected": "3.9.1"
        },
        {
            "introduced": "3.9.2"
        },
        {
            "last_affected": "3.9.2"
        },
        {
            "introduced": "3.9.3"
        },
        {
            "last_affected": "3.9.3"
        },
        {
            "introduced": "3.9.4"
        },
        {
            "last_affected": "3.9.4"
        },
        {
            "introduced": "3.9.5"
        },
        {
            "last_affected": "3.9.5"
        },
        {
            "introduced": "3.9.6"
        },
        {
            "last_affected": "3.9.6"
        },
        {
            "introduced": "3.9.7"
        },
        {
            "last_affected": "3.9.7"
        },
        {
            "introduced": "3.9.8"
        },
        {
            "last_affected": "3.9.8"
        },
        {
            "introduced": "3.10.0"
        },
        {
            "last_affected": "3.10.0"
        },
        {
            "introduced": "3.11.0"
        },
        {
            "last_affected": "3.11.0"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

3.*
3.10.0
3.11.0
3.9.0
3.9.1
3.9.2
3.9.3
3.9.4
3.9.5
3.9.6
3.9.7
3.9.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-4960.json"

Git / github.com/cloudfoundry/uaa-release

Affected ranges

Type
GIT
Repo
https://github.com/cloudfoundry/uaa-release
Events
Database specific
{
    "cpe": [
        "cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:21:*:*:*:*:*:*:*",
        "cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:22:*:*:*:*:*:*:*",
        "cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:23:*:*:*:*:*:*:*",
        "cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:24:*:*:*:*:*:*:*",
        "cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:24.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:24.2:*:*:*:*:*:*:*",
        "cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:24.3:*:*:*:*:*:*:*",
        "cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:24.4:*:*:*:*:*:*:*",
        "cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:24.5:*:*:*:*:*:*:*",
        "cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:24.6:*:*:*:*:*:*:*",
        "cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:25:*:*:*:*:*:*:*",
        "cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:26:*:*:*:*:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "21"
        },
        {
            "last_affected": "21"
        },
        {
            "introduced": "22"
        },
        {
            "last_affected": "22"
        },
        {
            "introduced": "23"
        },
        {
            "last_affected": "23"
        },
        {
            "introduced": "24"
        },
        {
            "last_affected": "24"
        },
        {
            "introduced": "24.1"
        },
        {
            "last_affected": "24.1"
        },
        {
            "introduced": "24.2"
        },
        {
            "last_affected": "24.2"
        },
        {
            "introduced": "24.3"
        },
        {
            "last_affected": "24.3"
        },
        {
            "introduced": "24.4"
        },
        {
            "last_affected": "24.4"
        },
        {
            "introduced": "24.5"
        },
        {
            "last_affected": "24.5"
        },
        {
            "introduced": "24.6"
        },
        {
            "last_affected": "24.6"
        },
        {
            "introduced": "25"
        },
        {
            "last_affected": "25"
        },
        {
            "introduced": "26"
        },
        {
            "last_affected": "26"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

Other
21
22
23
24
25
26
v21
v22
v23
v24
v25
v26
24.*
24.1
24.2
24.3
24.4
24.5
24.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-4960.json"